Jonathan Johnson·May 21A Deep Dive into Codex Windows SandboxOpenAI recently published a writeup on their new Windows sandbox design. The post covers the areas they explored, the options they…A response icon2A response icon2
Jonathan Johnson·May 11EtwWatcherA research passion of mine is telemetry. This could be the identification of new telemetry sources, how to tap into telemetry sources to…
Jonathan Johnson·Apr 20Windows ProjFS Internals: A Technical Deep DiveOriginally published at Windows ProjFS Internals: A Technical Deep Dive | Huntress.
Jonathan Johnson·Dec 18, 2025RAG, ICL, and Windows Events: Building a Human-Guided Security AnalystIntroduction
Jonathan Johnson·Sep 29, 2025Peeling Back the Mask: How the Threat Intelligence Provider is ProtectedIntroduction
Jonathan Johnson·Jun 6, 2025No Agent, No Problem: Discovering Remote EDRAs the reader, I’m sure you’re thinking — “oh great, another EDR internals or bypass post”. I can fully understand that sentiment, as…
Jonathan Johnson·Mar 17, 2025The Truth About Telemetry: The Role of Primary and Secondary Telemetry SourcesDetection Engineers, Threat Hunters, and SOC Analysts all rely on one critical thing to do their jobs effectively — telemetry. However…
Jonathan Johnson·Dec 4, 2024Behind the Mask: Unpacking Impersonation EventsIntroductionA response icon2A response icon2
Jonathan Johnson·Oct 31, 2024Silencing the EDR SilencersOriginally posted: Silencing the EDR Silencers | Huntress (huntress.com) authored by me.